Privacy Policy
Last updated 21 September 2026.
This is a plain-English draft and has not been reviewed by a lawyer. Have it checked before taking money from customers.
Who we are
TagVault is operated by Krown Digital, Perth, Western Australia. We can be reached at hello@tagvault.com.au.
Whose data is in TagVault
Two different groups, and the distinction matters:
- Operators — the test & tag businesses who subscribe. We hold their account details, business name, ABN, technician names and billing records.
- Operators' clients — the businesses whose equipment is tested. We hold their site addresses, asset records, test results and a billing contact. We hold this on behalf of the operator, not for our own purposes.
What we collect
- Account and sign-in details, handled by our authentication provider.
- Asset registers, test results, photographs attached to tests, and the location recorded at the time of a test.
- Client names and contact details entered by the operator.
- Billing records, handled by our payment providers. We never see or store card numbers.
- Basic diagnostic logs.
What we do not do
- We do not sell data to anyone, ever.
- We do not use operator or client data to train machine-learning models.
- We do not contact an operator's clients on our own initiative. Reminders are sent in the operator's name and only after that operator has approved the specific message.
- We do not advertise to anyone in the product.
Where it lives
Application data is stored with our hosting and database providers, which may process data outside Australia. Payment data is handled by our payment providers under their own terms.
Getting your data out
Every record can be exported as CSV at any time, from inside the product, including while a subscription is lapsed or cancelled. This is deliberate: the records are the operator's, and we will not hold them hostage.
Deletion
An operator can ask us to delete their account and data by email. We will do so within 30 days, except where we must keep billing records for tax purposes. Note that test records may be evidence an operator or their client needs to keep — consider exporting before deleting.
Access and correction
Under the Australian Privacy Act you may ask what personal information we hold about you and ask us to correct it. Email us and we will respond within a reasonable time.
Security
Access to an operator's data requires authentication and is scoped to their organisation. Client portal links are unguessable, individually revocable, and stored only as a hash. No system is perfectly secure; if we become aware of a breach affecting your data we will tell you.
Changes
If we change this policy materially we will email account holders rather than quietly updating this page.